Cross-Site Scripting Vulnerability in Leetoo Toocheke Companion Plugin
CVE-2025-23992
5.9MEDIUM
What is CVE-2025-23992?
The Leetoo Toocheke Companion plugin for WordPress is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts. This issue affects versions from n/a up to 1.166, enabling stored XSS attacks where the malicious code is saved and executed when other users access the compromised page. Website owners using this plugin should prioritize patching or updating to mitigate the risk of potential exploitation.
Affected Version(s)
Toocheke Companion 0 <= 1.166